HIPAA Critical

Follow HIPAA Critical
Share on
Copy link to clipboard

HIPAA compliance is complicated. And it only gets harder with hackers targeting Healthcare more than ever. Join host Olena Heu and the Paubox team as they discuss news and trends in healthcare information security. Also enjoy engaging interviews with leaders in cybersecurity, InfoSec, healthcare, an…

Paubox


    • Apr 17, 2026 LATEST EPISODE
    • monthly NEW EPISODES
    • 19m AVG DURATION
    • 73 EPISODES


    Search for episodes from HIPAA Critical with a specific topic:

    Latest episodes from HIPAA Critical

    Brockton Hospital hit by cyberattack, incident disrupts patient care

    Play Episode Listen Later Apr 17, 2026 4:21 Transcription Available


    This episode examines recent ransomware attacks affecting Brockton Hospital, Stockton Cardiology, and Rocky Mountain Care, alongside a Dutch supply chain breach impacting eleven hospitals. The hosts discuss the EvilTokens phishing kit that bypasses MFA through Microsoft 365 device code flow exploitation, and share practical defenses including conditional access policies, improved logging, and incident response planning. Key insights from the April Zoom social mixer cover monthly penetration testing, effective security awareness training, and AI adoption guardrails.

    Da Vinci robot maker Intuitive Surgical reports phishing breach

    Play Episode Listen Later Apr 10, 2026 4:23 Transcription Available


    This episode examines recent cybersecurity incidents affecting healthcare organizations, including breaches at Intuitive Surgical, Nacogdoches Memorial Hospital, and Innovative Pharmacy Packaging Corp, alongside a sophisticated job scam targeting professionals. Key takeaways include the critical importance of phishing training, network monitoring, vendor risk assessments, and reducing detection dwell time. The discussion reinforces that most breaches stem from preventable issues like misconfigurations, blind spots, and social engineering vulnerabilities.

    Microsoft Teams phishing campaign deploys A0Backdoor malware 

    Play Episode Listen Later Apr 3, 2026 3:53 Transcription Available


    In this episode, Alex and Jen break down three recent cybersecurity incidents affecting healthcare and social services organizations: Microsoft Teams impersonation attacks targeting healthcare and financial sectors, fake AI apps harvesting credentials, and a ransomware breach at a nonprofit serving vulnerable populations. The discussion highlights how misconfigurations and overlooked security basics create exploitable gaps, and offers practical steps for locking down external communications, verifying app legitimacy, and strengthening defenses against ransomware.

    Navia Benefit Solutions announces breach impacting nearly 3 million

    Play Episode Listen Later Mar 27, 2026 4:01 Transcription Available


    In this episode, we break down recent healthcare cybersecurity incidents including the Navia benefits administrator breach affecting nearly three million individuals, ransomware attacks on Kettering Health and a US healthcare provider, and the Essen Medical Associates settlement. We examine common vulnerabilities across these cases—from inadequate privileged access monitoring to untested incident response plans—and discuss actionable steps organizations can take to strengthen their security posture. The key takeaway: most breaches stem from addressable gaps, and consistent attention to fundamentals remains the most effective defense.

    Paubox recognized as email encryption leader in G2 Spring 2026 Reports

    Play Episode Listen Later Mar 20, 2026 4:00 Transcription Available


    In this episode, Alex and Jen break down the latest cybersecurity incidents affecting healthcare, including ransomware targeting community health organizations, phishing attacks leveraging trusted cloud platforms, MFA bypass techniques, and the exploitation of legitimate admin tools in cloud environments. The discussion emphasizes that most breaches stem from preventable configuration gaps and offers actionable guidance on endpoint protection, network segmentation, and phishing-resistant authentication methods.

    68. Aja Anderson: "Bad actors are offering your employees incentives to help them."

    Play Episode Listen Later Mar 16, 2022 22:44


    Episode 68 features Aja Anderson, Paubox Customer Success Manager. 

    67. Aja Anderson: "The gaps in cybersecurity are not complicated, hyper-technical ones. They're just basic user errors."

    Play Episode Listen Later Feb 22, 2022 19:10


    Episode 67 features Aja Anderson, Paubox Customer Success Manager. 

    66. Hoala Greevy: "Just automating one workflow creates an instant ROI for the business"

    Play Episode Listen Later Feb 15, 2022 15:24


    Episode 66 of HIPAA Critical features an interview with Founder CEO, Hoala Greevy, about workflow automation. 

    65. Aja Anderson: "That's the sweet spot for threat actors coming after you because they know that there's money there."

    Play Episode Listen Later Jan 19, 2022 15:57


    Episode 65 of HIPAA Critical recaps the HIPAA Breach Report details breaches from December 2021. 

    64. Dave Ledoux: "I'm ready to pivot at any time."

    Play Episode Listen Later Dec 1, 2021 22:29


    Episode 64 of HIPAA Critical features an interview with Dave Ledoux, CIO of Innovive Health. 

    63. Aja Anderson: "As long as people can make money, they're gonna keep [attacking]. As long as your systems are not secure, you're at risk."

    Play Episode Listen Later Nov 10, 2021 16:10


    Episode 63 of HIPAA Critical features a discussion with Aja Anderson on this month's Paubox HIPAA Breach Report. 

    62. Hector Rodriguez: "In healthcare, we have the challenges of cybersecurity, disaster recovery, and recovery strategies for ransomware mitigation."

    Play Episode Listen Later Nov 3, 2021 20:19


    Episode 62 of HIPAA Critical features an interview with Hector Rodriguez, Principal Industry Specialist, Healthcare & Life Sciences - AWS

    61. Su Bajaj: "The value of AI is what it's doing for you. It's not to replace people but to augment and make us more efficient and catch threats."

    Play Episode Listen Later Oct 27, 2021 19:16


    Episode 61 of HIPAA Critical features an interview with Su Bajaj, CTO of Compex Legal. 

    60. Brian Fritton: "If you make it easy for attackers to find email addresses, they're gonna phish you."

    Play Episode Listen Later Oct 20, 2021 21:56


    Episode 60 of HIPAA Critical features an interview with Brian Fritton, CEO of Havoc Shield. 

    ceo addresses phish attackers make it easy fritton brian fritton havoc shield
    59. Aja Anderson: "If you don't have something that's actually examining your encrypted HTTPS traffic, you're missing 9 out of 10 instances of malware."

    Play Episode Listen Later Oct 13, 2021 25:55 Transcription Available


    Episode 59 of HIPAA Critical covers the Paubox HIPAA Breach Report for October 2021 and other cybersecurity trends with guest Aja Anderson, Paubox Customer Success Manager. 

    58. Matt Cooper: "The eternal weakness is human error."

    Play Episode Listen Later Oct 6, 2021 23:13


    Episode 58 of HIPAA Critical includes an interview with Matt Cooper, Cybersecurity & Data Privacy Principal at Vanta. 

    57. Hoala Greevy: "It's a matter of sorting the data, training the data, and then using those new learnings to provide greater phishing detection."

    Play Episode Listen Later Sep 22, 2021 15:45


    Episode 57 of HIPAA Critical features an interview about AI with Paubox Founder CEO, Hoala Greevy. 

    56. Sara Sosa: "An informed team is an effective team."

    Play Episode Listen Later Sep 15, 2021 11:57


    Episode 56 of HIPAA Critical features an interview with Sara Sosa, Director of Information Services at Vista Care. 

    55. Aja Anderson: "It is frustrating to take the extra steps, yet it is keeping us safe."

    Play Episode Listen Later Sep 8, 2021 14:41


    Episode 56 of HIPAA Critical welcomes back Paubox Customer Success Manager, Aja Anderson, to discuss the findings of the Paubox HIPAA Breach Report for September 2021.  

    54. Jane Harper: "All organizations have some risks. Risk is inherent."

    Play Episode Listen Later Sep 1, 2021 19:51 Transcription Available


    Episode 54 includes an interview with Jane Harper. Jane is the senior director, information security risk management and business engagement at Eli Lilly and Company. 

    53. Anshul Pande: "All of these changes brought about a new set of problems to solve and challenges as we implemented those technologies."

    Play Episode Listen Later Aug 18, 2021 17:06


    Episode 53 of the HIPAA Critical podcast features an interview with Anshul Pande, vice president and chief technology officer at Stanford Children's Health. 

    52. Aja Anderson: "No matter how tight your budget is you should routinely assess the risk of your systems."

    Play Episode Listen Later Aug 11, 2021 20:14 Transcription Available


    Episode 52 of HIPAA Critical welcomes back Paubox Customer Success Manager, Aja Anderson, to discuss the findings of the Paubox HIPAA Breach Report for August 2021. 

    51. Dr. Eric Cole: "It's the same fundamental problem: we're not learning our lessons and keep repeating them over and over again."

    Play Episode Listen Later Aug 4, 2021 21:08 Transcription Available


    Episode 51 of HIPAA Critical includes an interview with Dr. Eric Cole, a former CIA hacker and founder of Secure Anchor.Read the transcript here. More about Paubox: www.paubox.com 

    50. Fred Kwong: "Risk is a language that business understands."

    Play Episode Listen Later Jul 21, 2021 22:38 Transcription Available


    Fred Kwong, CISO of Delta Dental is featured on episode 50 of HIPAA Critical.Read the full transcription here.  

    49. Aja Anderson: "This isn't unique to healthcare. This is happening in every industry."

    Play Episode Listen Later Jul 14, 2021 16:29 Transcription Available


    Episode 49 covers the findings of the Paubox HIPAA Breach Report for July 2021. Aja Anderson, customer success manager at Paubox, joins the episode to discuss key trends, share insights, and give cybersecurity tips. 

    48. Todd Pang: "We had to do a lot of training and awareness building for what actually constitutes PHI."

    Play Episode Listen Later Jul 7, 2021 36:14


    Episode 48 of the HIPAA Critical Podcast includes an interview with Todd Pang, president and co-owner of Caring Manoa. 

    47. Jeff Karlsson: "The Biggest Threat That Our Customers Have Is Not Having a Contingency Plan."

    Play Episode Listen Later Jun 16, 2021 15:21 Transcription Available


    The challenges of 2020 are still lingering in many industries we might be in a new year. But the effects of the covid-19 pandemic reach far and wide. The way we work and the way business operated changed dramatically and almost overnight. Jeff Karlsson is on today's episode. Jeff is the chief operating officer of Divergent Business Consulting, a Salesforce and financial consulting company. Jeff and Sierra Langston sit down to discuss the COVID-19 pandemic, how to force change across many industries, and emerging healthcare trends. 

    46. John Benbrook: "In Order to Safeguard That Sensitive Information, We Needed to Implement Encryption."

    Play Episode Listen Later Jun 9, 2021 11:22 Transcription Available


    Elderly care organizations need to comply with HIPAA regulations and security rules, especially if they deal with their patient's medications, doctors, or other sensitive information. What is the best way for these types of organizations to approach HIPAA compliance and secure data? How do we keep the most vulnerable members of our society safe from bad actors? John Benbrook, president of Oasis Senior Partners, and Paul Giovacchini, enterprise customer success manager at Paubox, join Sierra Langston on today's episode to discuss HIPAA compliance training, assessing risk management, and unencrypted data vulnerabilities.

    45. Greg Reber: "This Is the Biggest Information Breach That We've Ever Seen."

    Play Episode Listen Later Jun 2, 2021 22:20


    Cybersecurity protocols and practices will never be a one-size-fits-all solution. Different industries have different requirements for compliance. Healthcare has vague but vast security rules to follow under HIPAA. So how do organizations stay ahead of the cybersecurity curve?Greg Reber, Founder and CEO, of AsTech Consulting, is with us on today's episode. He and Sierra Langston discuss the changes and challenges in cybersecurity, including implementing solutions that meet regulatory standards, the evolving threat landscape, and how information sharing is a key to the future of cybersecurity.

    44. Jared Vinson: "It Started With a Phishing Attack, but It Ended With a Whole Mess of Other Things."

    Play Episode Listen Later May 26, 2021 13:25


    With more than 500 reported HIPAA breaches in the last year, why are healthcare organizations slow to update their cybersecurity protocols and technology stacks? Is it possible for the healthcare industry to get ahead of bad actors? Today, Sierra Langston speaks with Jared Vinson, director of cybersecurity at Hill Country Tech Guys on all things healthcare security, including phishing scams, best practices, and the aftermath of a HIPAA breach.

    43. Michael Mead: "Training Is Not Just for HIPAA Security, but Cybersecurity."

    Play Episode Listen Later May 19, 2021 14:17 Transcription Available


    The healthcare industry is slow to change and, at times, even slower to embrace innovation. Fax machines, patient portals, and complicated compliance solutions are everywhere. The challenges of these outdated and vulnerable technologies only make data breaches, HIPAA fines, and cybersecurity threats more prevalent.  On today's episode, Sierra Langston and Michael Mead of The Medical Cost Savings Solution discuss HIPAA compliance, healthcare industry challenges, and unencrypted data transfers.

    42. Bonnie Castonguay: "What We've Always Wanted Was the Ability for More Seniors to Have Access to Home Care."

    Play Episode Listen Later May 12, 2021 22:41


    Almost overnight, the pandemic changed telehealth and how our most vulnerable populations receive the medical care they desperately need.  As many Americans start to take care of their aging parents at home or through an elder care center, they find navigating the complicated world of HIPAA and the American healthcare system to be confusing, expensive, and daunting. On today's episode, Paubox Founder and CEO, Hoala Greevy, interviews Bonnie Castonguay, co-founder of Ho'okele Health on the effects COVID-19 has on in-home care, the positive changes telehealth has brought to her clients and their families, and how easy Paubox has made HIPAA compliance for her company. 

    41. Eoin Gregory: "You Say the Word HIPAA, and Our Providers Cringe or Turn Their Brains off."

    Play Episode Listen Later May 5, 2021 16:03


    If you work in healthcare, you know what HIPAA is, but do you and your organization understand how to maintain HIPAA compliance regarding email security and encryption? Is HIPAA compliance a “one size fits all” situation? How do organizations keep their employees and their partners compliant and safe?Today Sierra Langston sits down with Eoin Gregory of Family Billing Solutions and Travis Taylor of Paubox to discuss email encryption, the HHS Wall of Shame, and how to keep your staff, partners, and yourself educated on the vague but vast world of HIPAA compliance.

    40. Ken Dabkowski: "As a Tech-Centered Company, We Want to Make Sure We're Meeting the Highest Standards Possible."

    Play Episode Listen Later Apr 28, 2021 13:30


    What is medical cost-sharing? Is it the future of healthcare? What can modern healthcare learn from this historical industry? In this episode, Sierra Langston sits down with Ken Dabkowski, Senior Project Manager of Sedera, to discuss medical cost-sharing and Sedera's IT and cybersecurity stack.

    39. Hannah Trum: "Certifications are a No-Brainer in the Healthcare Industry."

    Play Episode Listen Later Apr 14, 2021 10:24


    In this episode, you'll hear Sierra Langston, marketing manager, and Hannah Trum, marketing specialist, give their top takeaways from Paubox Spring Summit, Secure Communication During a Pandemic. Panelists from this event include:Hoala Greevy, Founder CEO, PauboxAnshul Pande, Vice President, and Chief Technology Officer, Stanford Children's HealthChris Lindley, Chief Population Health Officer, Vail HealthJulie Jackson, Director Applications and Informatics, Vail HealthSusan Ibáñez, Chief Information Officer, Vail HealthPaddy Padmanabhan, CEO, Damo Consulting, Inc.Aaron Collins, System Administrator, Developmental Center of the OzarkBrian Kline, Principal, Webb AdamsDan Dorszynski, Software Engineer, PauboxHoward Rosen, MBA, CEO & Founder, LifeWIREMatthew Wallace, Vice President of Strategic Initiatives and Partnerships, Easterseals LouisianaMichael Mead, BCPA, Chief Operating Officer, The Medical Cost Savings SolutionMichael Parisi, Vice President, Business Development & Adoption, HITRUSTNick Wong, Email API Specialist, PauboxTony UcedaVélez, CEO & Founder, VerSpriteFor a full recap of Paubox Spring Summit, click here. For more information about Paubox Spring Summit, click here. 

    38. Tony UcedaVélez "A Risk-Centric Approach is Trying to Prove the Most Likely Threats That Could Affect a Healthcare Entity."

    Play Episode Listen Later Mar 31, 2021 16:00


    You may be asking yourself what threat modeling is and why it is important?In this episode, that is what you are going to find out. Healthcare has been under attack for a slew of reasons for the past 10 years. Threat modeling, very simply put, is a way to model threats. Whether you are in healthcare tech or an insurance provider, there is a benefit to understanding who your adversaries are and where you are vulnerable to threat actors.Today we are speaking with Tony UcedaVélez, founder and CEO of the security consulting firm VerSprite, based in Atlanta. 

    37. Brian Kline "Writing a Policy that Prohibits Sending Sensitive Information is Probably Not a Realistic Option"

    Play Episode Listen Later Mar 18, 2021 13:15


    Have you ever wondered how to streamline HITRUST, SOC 2 as well as other certifications and attestations?Well, in this episode, that is what you will find out.We’re going to explain how to streamline the process of developing policies and procedures, how to conduct a gap assessment & risk assessment, how to facilitate incident response exercises, how to upload evidence and meet with auditors.

    36. Anya Schiess “Telemedicine is Just an Example of What COVID has Catalyzed”

    Play Episode Listen Later Mar 3, 2021 13:15


    Today, we're talking with Anya Schiess, Co-founder and General Partner of Healthy Ventures. She will shed light on a variety of topics such as challenges for health systems, why modern data architecture is important, FinTech, and what is on the horizon for healthcare.

    35. Elena Yau “Email Is The Most Convenient But Is Also The Highest Threat.”

    Play Episode Listen Later Feb 18, 2021 13:02


    Ransomware, malware, phishing attacks, and PHI email breaches continue to spike in 2021.Malware, the malicious software, is built to exploit chinks in the armor of our operating systems. This can involve pop-up ads or using it as part of a distributed denial-of-service attack.This is why HIPAA Compliant training is so important.Have you ever wondered how other healthcare organizations are training their team on HIPAA Compliance or protecting their email?Well, in this episode, that is what you will find out.Elena Yau, Director of IT and HIPAA Security Officer at FiveAcres is going to give you an in-depth look at their HIPAA compliance processes and procedures.

    34. Bruce Snell "There's Going To Be Vulnerabilities Out There That There's Not A Fix For Yet."

    Play Episode Listen Later Feb 3, 2021 15:22


    Have you ever wondered how to mitigate the vulnerabilities that stem from IoT.Well, in this episode, that is what you will find out.We’re going to provide you with common vulnerabilities and current risks with devices that you use every day. Smartwatches and modern cars to name a few. Today, we have Bruce Snell, Global Vice President of Cybersecurity Strategy and Transformation at NTT Security, to discuss this topic in greater detail.

    33. Matthew Wallace “COVID-19 Brought an Overnight Change to Our Organization”

    Play Episode Listen Later Jan 20, 2021 11:45


    Have you ever wondered how other businesses and practices are overcoming the challenges of maintaining HIPAA Compliance?Well, in this episode, that is what you’ll find out. Amongst the slew of HIPAA violations such as lack of employee training, medical record mishandling, hacking and malware, improper disposal of PHI, lies one HIPAA violation that we will be discussing in great detail, using nonsecure technology to share PHI.Matthew Wallace, Vice President of Strategic Initiatives and Partnerships at Easterseals Louisiana is going to fill us in on how they are able to maintain HIPAA compliance and what they have changed within their business because of COVID.

    32. Kurt Hagerman "The Key for Healthcare is Understanding and Containing the Risks as Best You Can"

    Play Episode Listen Later Jan 7, 2021 15:43


    The Internet of Things is transforming healthcare from telemedicine to augmented reality to AI. All systems, network mobility, collaboration, security etiquette need to connect and work together. Have you ever wondered how to mitigate the vulnerabilities that stem from IoT? Well, in this episode, that is what you will find out. We're going to give you key points for building or maintaining your overall cybersecurity strategy, as well as provide examples of how IoT is a real and growing force in healthcare.

    31. Aaron Collins: “Covid Has Drastically Changed Our Approach to IT Security" ”

    Play Episode Listen Later Dec 23, 2020 12:51


    Have you ever wondered how you may be leaving yourself open for a data breach? Well, in this episode, that is what we will be covering. We’re going to give you an overview of the biggest threats in Healthcare right now and provide examples of how you may be vulnerable to a threat actor. Aaron Collins, System Administrator for the Developmental Center of the Ozarks, will discuss these topics in greater detail.

    30. Travis Taylor: “With Email API We Are Looking to Automate A Lot of Processes”

    Play Episode Listen Later Dec 9, 2020 20:47


    Have you ever wondered how an Email API can be beneficial for Healthcare businesses and covered entities? Well, in this episode, that’s what you’ll find out. We’re going to give you an overview of why healthcare businesses choose an Email API in general and, more specifically, how an Email API can be utilized for contact tracing.

    29. Greg Hoffman: "Helping individuals & companies solve problems with their security & compliance vulnerabilities"

    Play Episode Listen Later Nov 25, 2020 17:03


    In this episode, we’re going to give you 5 tips to ensure you are protected from cybercriminals while working from home and dive into new threats and trends in the Healthcare industry.

    HIPAA Critical Podcast Episode 28 | Mike Docktor: ‘’There Has to Be a Better Way for Clinicians to Interact With Patients"

    Play Episode Listen Later Nov 11, 2020 35:02


    Have you ever wondered how to maintain HIPAA compliance within your task management platforms? In this episode, that's what you are going to find out and a whole lot more. Whether you are in IT, a physician, or on the administrative side, this podcast is for you.

    Maegan Megginson: 'Therapy Will Continue To Become More Focused On Telehealth'

    Play Episode Listen Later Oct 28, 2020 12:58


    Are you wondering how practices are offering Telehealth options to their patients? Or making money during COVID? Well, in this episode, that's exactly what you'll find out. Mental health and wellness during the COVID-19 pandemic has changed significantly. We will delve deeper into this with Maegan Megginson, Certified Sex Therapist, from The Center for Couples and Sex Therapy.

    Nick Wong: 'Email API Solutions Can Easily Integrate into COVID Test Result Delivery Applications'

    Play Episode Listen Later Oct 14, 2020 19:40


    In this episode, we're going to give you an overview of the Email API solution process using contact-tracing and COVID test result delivery applications. By the end, you'll know more about contact tracing, specifically, and how to utilize an Email API solution.

    NIST Cybersecurity Standards, $6.85 Million Breach Settlement & Paubox SECURE @ Home

    Play Episode Listen Later Sep 30, 2020 9:29


    A new report shows only half of Healthcare Providers are meeting NIST Standards, Premera Blue Cross pays a hefty fine to the Office of Civil Rights, and more details on October's Paubox SECURE@ Home Virtual Conference...it's free to join the conference.

    Paubox SECURE, TLSv1.3 Project, Punahou School Success Story, Working from Alaska

    Play Episode Listen Later Sep 16, 2020 14:03


    This week on the HIPAA Critical Podcast, Hoala Greevy chats about working remotely from Alaska, details on Paubox SECURE, and how you can attend for free. We also discuss HIPAA violations, ransomware, and phishing attacks, and Punahou School is another Paubox success story to share.

    Ransomware Trends, Lures & Red Flags, Tesla Makes Headlines & Anders Norremo from ThirdPartyTrust

    Play Episode Listen Later Sep 2, 2020 23:40


    Tesla thwarted a ransomware attack and is making global headlines. We discuss lures and seven ransomware red flags. Henderson Behavioral Health is winning, and UCSF pays more than a million dollars to hackers. Anders Norremo from ThirdPartyTrust chats about his unique platform and Third-party Risk Management.

    Claim HIPAA Critical

    In order to claim this podcast we'll send an email to with a verification link. Simply click the link and you will be able to edit tags, request a refresh, and other features to take control of your podcast page!

    Claim Cancel